VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (530)

page 24 of 27
  • CVE-2018-4847MedApr 23, 2018
    risk 0.30cvss 4.6epss 0.00

    A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the…

  • CVE-2017-8769MedMay 18, 2017
    risk 0.30cvss 4.6epss 0.00

    Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion to occur upon chat…

  • CVE-2025-43274MedJul 30, 2025
    risk 0.29cvss 4.4epss 0.00

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2023-33228MedNov 1, 2023
    risk 0.29cvss 4.5epss 0.00

    The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information.

  • CVE-2021-20567MedJun 16, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.

  • CVE-2020-3389MedAug 26, 2020
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists because sensitive information is stored…

  • CVE-2019-2231MedDec 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…

  • CVE-2018-1938MedMar 5, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318.

  • CVE-2018-1937MedMar 5, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.

  • CVE-2026-84676MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-64147MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-64146MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-64145MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-64144MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-64143MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2023-30523MedApr 12, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file…

  • CVE-2022-34307MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.01

    IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and…

  • CVE-2015-3207MedJul 7, 2022
    risk 0.28cvss 5.3epss 0.01

    In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.

  • CVE-2021-38977MedNov 15, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…

  • CVE-2021-29883MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site…